Ostium Exploit Traced to Fraudulent Bitcoin Price Reports
Key Takeaways
- •Ostium lost 23.75 million USDC from its OLP vault on July 15 due to an off-chain infrastructure breach that allowed an attacker to submit fraudulent BTC-USD price reports.
- •The exploit did not compromise Ostium's smart contracts, multisig wallets, or trader collateral, with losses confined solely to the OLP liquidity vault.
- •Automated monitoring systems detected the suspicious activity and stopped further withdrawals before additional funds could be extracted.
- •Ostium migrated to a new production environment with updated security controls and resumed trading services on July 23, eight days after the incident.
- •A dedicated recovery plan for affected liquidity providers is being prepared, with further details to be announced once finalized.

Ostium has attributed the July 15 exploit that drained 23.75 million USDC from its OLP vault to an off-chain infrastructure breach. The perpetuals exchange confirmed that its smart contracts and protocol multisigs were not compromised.
In a post-mortem published on Wednesday, Ostium explained that the attacker gained unauthorized access to off-chain systems and submitted false BTC-USD price reports to the protocol. The incident underscores a recurring challenge in decentralized finance, where protocols may undergo rigorous smart contract auditing yet remain exposed through the off-chain infrastructure that feeds pricing, settlement, or operational data to on-chain systems.
Attack Vector and Execution
The fraudulent price reports enabled the attacker to record artificial trading profits. All stolen funds were drawn from the public OLP vault, which supplies liquidity for trading activity on the platform.
The attacker utilized forwarder paths already recognized by the protocol. An initial test position of 100 USDC generated approximately 897.8 USDC in false profit before the attacker proceeded with larger transactions.
The primary batch transferred 11.9 million USDC to a beneficiary wallet. The attacker subsequently executed six additional standalone trading cycles using the same method, bringing the total loss to 23.75 million USDC.
Ostium stated that its automated monitoring systems detected the suspicious activity and prevented further withdrawals before additional funds could exit the vault.
Smart Contracts and User Funds Unaffected
Ostium's investigation found no evidence of vulnerabilities in its smart contract code. The team also reported no signs that attackers had seized control of the multisig wallets used to manage the protocol.
Trader collateral remained unaffected by the breach. User margin stayed secured within the protocol's trading contracts, with losses confined to funds held in the OLP liquidity vault.
The platform has since migrated its operations to a new production environment featuring updated security controls. Ostium resumed trading services on July 23 after completing the transition. The speed of resumption, combined with the pending recovery plan, will likely be closely watched by liquidity providers evaluating whether to re-engage with the protocol.
Ostium is preparing a separate recovery plan for affected liquidity providers and stated it will release further details once the plan is finalized.